Security: gtsteffaniak/filebrowser
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
`GET /public/api/media/metadata` returns file content to anonymous share visitors, ignoring the share's download limit and file-viewer settingGHSA-55mw-cwg7-m8f5 published
Sep 4, 2026 by gtsteffaniakModerate -
Broken Access Control in /api/users Allows Self-Targeted Privilege EscalationGHSA-p5cc-4p84-c4m2 published
Aug 29, 2026 by gtsteffaniakHigh -
Stored XSS via HTML Preview — `<script>` Whitelist + `allow-same-origin` Sandbox EscapeGHSA-vvm6-jwrf-hgmg published
Aug 29, 2026 by gtsteffaniakHigh -
Share authorization gaps let read-only users delete filesGHSA-x79q-5hqm-x839 published
Aug 15, 2026 by gtsteffaniakHigh -
Share path re-point allows scope escape (arbitrary read/write across the source root)GHSA-wfjp-qhvc-69wp published
Aug 15, 2026 by gtsteffaniakHigh -
Logout Bypass via Alternate JWT SpellingGHSA-8m35-wcjh-95q7 published
Aug 15, 2026 by gtsteffaniakModerate -
FileBrowser Quantum: file-upload / mkdir authorization uses the scope-relative path, bypassing per-user access-rule denials (write into a restricted directory)GHSA-cw65-p35p-633w published
Aug 15, 2026 by gtsteffaniakModerate -
Absolute Path Traversal Bypass in SanitizeUserPath allows authenticated arbitrary file read outside user scopeGHSA-rqqq-wv83-rp74 published
Aug 15, 2026 by gtsteffaniakModerate -
Improper authorization in public upload endpoint allows anonymous bypass of er-folder DENY ACLs via Scope-Stripped path keyGHSA-qv53-4557-m65h published
Aug 15, 2026 by gtsteffaniakHigh -
Improper session revocation allows authentication bypass via revoked-JWT resurrection in `extractUserFromExpiredToken`GHSA-4wmj-rq3c-m65v published
Aug 15, 2026 by gtsteffaniakModerate
Learn more about advisories related to gtsteffaniak/filebrowser in the GitHub Advisory Database